IP Library Granted Patent US 11,310,213
Granted Patent B2
US 11,310,213 · App. 15/057,490 · Granted Apr 19, 2022

Directory service user synchronization

Inventors: Kalyan Regula (Alpharetta, GA); Shravan Shantharam (Cumming, GA); Nishita Manjunath (Atlanta, GA); Varun Murthy (Atlanta, GA); Jason Roszak (Brookhaven, GA)
Assignee: AirWatch LLC
H04L63/08H04L63/102H04L67/1044H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,310,213
App. No.
15/057,490
Granted
Apr 19, 2022
Kind
B2
Abstract

Disclosed are various examples for enrolling a client device and synchronizing user attributes for the client device across multiple directory services. A search request for user attributes can be sent to a first directory service with an identifier for a user account. The first directory service can query for the identifier and send back user attributes. If a global identifier is included in the attributes, another search request for user attributes can be sent to a second directory service with the global identifier. The second directory service can query for the global identifier and send back user attributes.

Claims (44)

1. A method, comprising:

in an instance in which a user account comprising an identifier is detected as omitted from a list of managed users managed by a management service, searching a first directory service for a plurality of first user attributes based at least in part on the identifier;

receiving the plurality of first user attributes from the first directory service;

determining that the plurality of first user attributes includes a global identifier;

searching a second directory service for a plurality of second user attributes based at least in part on the global identifier;

receiving the plurality of second user attributes from the second directory service; and

enrolling a client device in the management service, the management service configured to enforce at least one compliance rule based on the user account being assigned to a group based on one of the plurality of second user attributes.

2. The method of claim 1 , further comprising receiving an authentication confirmation comprising the identifier from the client device, the client device being associated with the user account.

3. The method of claim 2 , further comprising updating a plurality of user properties corresponding to the user account based at least in part on at least one of: the plurality of first user attributes or the plurality of second user attributes.

4. The method of claim 3 , further comprising scheduling a periodic query of the first directory service and the second directory service for changes to the user account, wherein updating the plurality of user properties corresponding to the user account occurs in response to the periodic query.

5. The method of claim 1 , wherein the global identifier is an immutable identifier.

6. The method of claim 1 , further comprising:

detecting a conflict between the plurality of first user attributes and the plurality of second user attributes; and

resolving the conflict based at least in part on a last modified timestamp associated with a conflicting set of user attributes.

7. A non-transitory computer-readable medium embodying a program that, when executed by at least one computing device, causes the at least one computing device to at least:

in an instance in which a user account comprising an identifier is detected as omitted from a list of managed users managed by a management service, search a first directory service for a plurality of first user attributes based at least in part on the identifier;

receive the plurality of first user attributes from the first directory service;

determine that the plurality of first user attributes includes a global identifier;

searching a second directory service for a plurality of second user attributes based at least in part on the global identifier;

receive the plurality of second user attributes from the second directory service; and

enroll a client device in the management service, the management service configured to enforce at least one compliance rule based on the user account being assigned to a group based on one of the plurality of second user attributes.

8. The non-transitory computer-readable medium of claim 7 , wherein the program further causes the at least one computing device to at least receive an authentication confirmation comprising the identifier from the client device, the client device being associated with the user account.

9. The non-transitory computer-readable medium of claim 8 , wherein the program further causes the at least one computing device to at least update a plurality of user properties corresponding to the user account based at least in part on at least one of: the plurality of first user attributes or the plurality of second user attributes.

10. The non-transitory computer-readable medium of claim 9 , wherein the program further causes the at least one computing device to at least schedule a periodic query of the first directory service and the second directory service for changes to the user account, wherein updating the plurality of user properties corresponding to the user account occurs in response to the periodic query.

11. The non-transitory computer-readable medium of claim 7 , wherein the global identifier is an immutable identifier.

12. The non-transitory computer-readable medium of claim 8 , wherein the program further causes the at least one computing device to at least:

detect a conflict between the plurality of first user attributes and the plurality of second user attributes; and

resolve the conflict based at least in part on a last modified timestamp associated with a conflicting set of user attributes.

13. A system, comprising:

a data store;

at least one computing device in communication with the data store, the at least one computing device being configured to at least:

in an instance in which a user account comprising an identifier is detected as omitted from a list of managed users managed by a management service, search a first directory service for a plurality of first user attributes based at least in part on the identifier;

receive the plurality of first user attributes from the first directory service;

determine that the plurality of first user attributes includes a global identifier;

search a second directory service for a plurality of second user attributes based at least in part on the global identifier;

receive the plurality of second user attributes from the second directory service; and

enroll a client device in the management service, the management service configured to enforce at least one compliance rule based on the user account being assigned to a group based on one of the plurality of second user attributes.

14. The system of claim 13 , wherein the at least one computing device is further configured to at least receive an authentication confirmation comprising the identifier from the client device, the client device being associated with the user account.

15. The system of claim 14 , wherein the at least one computing device is further configured to at least update a plurality of user properties corresponding to the user account based at least in part on at least one of: the plurality of first user attributes or the plurality of second user attributes.

16. The system of claim 15 , wherein the at least one computing device is further configured to at least schedule a periodic query of the first directory service and the second directory service for changes to the user account, wherein updating the plurality of user properties corresponding to the user account occurs in response to the periodic query.

17. The system of claim 13 , wherein the global identifier is an immutable identifier.

18. The method of claim 1 , wherein the identifier comprises at least one of: an object ID and a User Principal Name.

19. The non-transitory computer-readable medium of claim 7 , wherein the identifier comprises at least one of: an object ID and a User Principal Name.

20. The system of claim 13 , wherein the identifier comprises at least one of: an object ID and a User Principal Name.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2022
From: REGULA, KALYAN; SHANTHARAM, SHRAVAN; MANJUNATH, NISHITA; MURTHY, VARUN; ROSZAK, JASON
To: AIRWATCH LLC
Reel/Frame 059220/0215 →